Pidoku
Securing Each Stage

Securing Each Stage

IntermediateTopic7 lessons~5h 25m

Lessons, in order

01 The Lifecycle MapSecurity controls for an AI application attach to seven stages: design, data, model, build, deploy, runtime, operate. Each attack from the previous topic is cheapest to stop at one … Intermediate 40 min 02 Data and TrainingData reaches a model by three routes: training and fine-tuning (it becomes behaviour), retrieval (it becomes context at query time) and memory (the system writes it for later). Each route … Intermediate 45 min 03 Models and Supply ChainA model is a dependency that runs with access to your data and GPUs, so it gets the treatment any dependency gets — and a little more, because a model file can contain executable code and … Intermediate 50 min 04 Build and TestIn an AI application, security-relevant behaviour is defined by things that are not traditionally "code": prompts, tool definitions, policies, routing rules, model versions. The build stage … Intermediate 45 min 05 Deployment and InfrastructureDeployment security for AI is ordinary cloud and Kubernetes hardening applied to an unusual workload: one that holds extremely valuable assets (weights, prompts, customer context), runs on … Intermediate 50 min 06 Runtime GuardrailsA guardrail is a check that runs on every request, around the model: on the input before the model sees it, on the output before anyone or anything acts on it, and on each tool call in … Intermediate 50 min 07 Monitoring and ResponsePrevention will sometimes fail, so you need to see an attack on an AI system and stop it. Seeing requires an audit trail that records not only what was done but what the model had read when … Intermediate 45 min

About this topic

An AI application passes through stages — design, data, model, build, deployment, runtime, operation — and each stage has controls that are cheap there and expensive anywhere else. This topic walks the lifecycle in order.

#LessonThe question it answers
01The Lifecycle MapWhich control belongs at which stage, and who owns it?
02Data and TrainingHow do I keep training, fine-tuning and retrieval data trustworthy and private?
03Models and Supply ChainHow do I know a model file is what it claims and safe to load?
04Build and TestWhat goes in CI for an AI application, and how do I red-team it?
05Deployment and InfrastructureHow do I isolate, harden and protect the serving environment?
06Runtime GuardrailsWhat do input and output checks achieve, and where do they stop?
07Monitoring and ResponseHow do I detect an attack on an AI system and respond to it?

Agents add enough that they have their own topic next: Securing Agents.

↑↓ navigate↵ openesc close

drag to pan · scroll to zoom